Spring Boot Attack Probe

Authorized self-pentest probe targeting Spring Boot-specific weaknesses. Tests Actuator endpoint exposure (/env, /heapdump, /loggers), Whitelabel error page info disclosure, h2-console exposure, Spring Security permitAll gaps, and SpEL/parameter-binding pitfalls. Use when the user asks to "pentest" their own Spring Boot app.

Dolphinllc 259ede5 6.1 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/offensive/web/spring-boot-attack-probe commit 259ede5c75

Frequently asked questions

npx skillmds@latest add dolphinllc/spring-boot-attack-probe